Insights
Notes on AI & cloud security
Practical writing on securing AI adoption, Microsoft Copilot, cloud security, and building security programs that pass real audits — drawn from the field.
GPT-6 Astra Hits the 'Critical' Cyber Threshold: What It Actually Changes for Defenders
OpenAI's GPT-6 Astra is the first model classified at the 'Critical' cybersecurity level under its own Preparedness Framework. Here's what that designation means operationally — for patch cadence, supply chain, SOC design, and AI governance — beyond the AGI headlines.
Using an LLM to Watch Your LLM: Reasoning Over Prompt Traffic to Catch Injection
Putting a model in front of your prompt and response traffic to spot prompt injection is a genuinely good detective control and a genuinely bad gate. The benefits, the risks teams underestimate — including that the detector is itself injectable — and how to deploy it without fooling yourself.
Two "AI Control Planes", Six Surfaces: Reading Microsoft Agent 365 Against Onyx Security
Microsoft Agent 365 hit GA on 1 May 2026; Onyx Security exited stealth in March with $40M. Both call themselves an AI control plane. They are not substitutes — here is the surface-by-surface read, the licensing change that made Agent 365 mandatory, and why neither gives you ISO 42001 evidence.
AI Governance Metrics and Executive Reporting: Dashboards a Board Will Actually Read
Coverage, timeliness, risk posture and assurance — the four metric families that make AI governance measurable, plus how to structure a one-page executive dashboard and the board narrative that goes with it.
AI Governance in Financial Services: Building on Model Risk Management, Not Beside It
Banks and insurers already have a mature discipline for governing algorithms that make consequential decisions. How to extend model risk management to generative and agentic AI — and where the existing framework genuinely doesn't reach.
After the AI Governance Maturity Assessment: Turning Findings Into a Roadmap That Actually Executes
A maturity assessment tells you where you stand. The hard part is what comes next. How to convert findings into a sequenced, resourced roadmap — dependency order, quick wins, ownership, and the reporting that keeps it funded.
Governing the Full AI Lifecycle: From Use-Case Intake to Model Retirement
A working AI lifecycle governance model — intake, risk tiering, impact assessment, design gates, launch criteria, production monitoring, periodic review and decommissioning — with the artifacts and evidence each stage produces.
The AI Governance Operating Model: Who Owns What Across Technology, Risk, Legal, Procurement and Audit
AI governance fails on ownership, not on frameworks. A working operating model — decision rights, a RACI across six functions, committee design, and the three-lines model applied to AI.
Implementing ISO/IEC 42001: Building an AI Management System on the ISMS You Already Have
A practical implementation path for ISO/IEC 42001 — scope, AI policy, impact assessment, Annex A controls and the Statement of Applicability — and how to reuse your ISO 27001 management system instead of building a second one.
Operationalizing the NIST AI RMF: Turning Four Functions Into Working Controls
The NIST AI Risk Management Framework tells you what good looks like, not how to run it on a Tuesday. Here's how I translate GOVERN, MAP, MEASURE and MANAGE into owners, artifacts, workflows and evidence an auditor will accept.
Governing AI in Onyx: A 3-Tier Policy Maturity Model for Copilot, Agents, SaaS & MCP
A practical, tiered set of governance policies for organizations running Onyx — covering AI assistants, agentic AI, SaaS connectors, and MCP — grouped by increasing maturity from foundational control to continuous assurance.
- Start here
Securely Adopting Microsoft 365 Copilot: A Phased Launch Playbook
A practical, phased approach to rolling out Microsoft 365 Copilot securely — discover oversharing, constrain interactions, instrument everything, then govern agents and shadow AI.
Securing a Power Platform AI Champions Environment: ISO 27001, ISO 42001 & NIST Mapped
How to configure a governed Power Platform environment for 200+ AI Champions and Builders working with production data — and exactly which ISO 27001:2022, ISO 42001, NIST CSF 2.0 and NIST AI RMF requirements each control satisfies.
Runtime Guardrails: Using Purview DLP to Constrain What Copilot Can Do
Once you've reduced oversharing, Purview DLP gives Copilot real-time guardrails — blocking sensitive prompts, risky web grounding, and labelled-content processing. Here's how to use it well.
Governing AI Agents at Scale: Power Platform, Copilot Studio & Connectors
AI agents widen your data-egress surface fast. A practical governance model for Power Platform, Copilot Studio, and third-party agent platforms like Onyx — ownership, connectors, boundaries, and evidence.
Data Classification for GenAI: Why Sensitivity Labels Come First
Classification is the foundation generative-AI security is built on. Why sensitivity labels must precede a Copilot rollout — and how to approach labelling without boiling the ocean.
Mapping AI Security to ISO 27001 (and Where ISO 42001 Fits)
How to bring generative-AI and Copilot risk into an existing ISO 27001 ISMS — and where the new ISO/IEC 42001 AI management system standard complements it.
Can You Investigate What Copilot Did? Audit, eDiscovery & Retention for AI
If your legal, risk, and audit stakeholders ask 'what did Copilot actually do?', you need an answer. How Purview Audit, eDiscovery, and retention make AI interactions reviewable and defensible.
Microsoft 365 Copilot Doesn't Leak Secrets — It Exposes Oversharing
The biggest Copilot risk isn't the model inventing leaks. It's that Copilot makes your existing permission and oversharing mistakes instantly discoverable. Here's why — and what to do.
Detecting Risky AI Use with Purview Insider Risk Management
File-level controls stop known-bad data. Insider Risk Management adds the missing dimension for AI: detecting risky users and behaviour patterns — with privacy built in.
Shadow AI: Controlling Unsanctioned GenAI Tools with Defender for Cloud Apps
Your Copilot governance means little if half the company is pasting data into unsanctioned AI sites. How to discover, classify, and control shadow AI with Defender for Cloud Apps and a layered policy.
The One-Page Secure Copilot Launch Checklist
A practical pre-launch and launch-gate checklist for rolling out Microsoft 365 Copilot securely — the whole phased method distilled into a single page you can hand to a pilot team.
Find and Fix SharePoint Oversharing Before You Roll Out Copilot
A practical method for discovering and remediating SharePoint and OneDrive oversharing — DSPM assessments, Data Access Governance, and Restricted Content Discovery — before Copilot makes it discoverable.
Prompt Injection Isn't SQL Injection: A Defence-in-Depth Approach to AI Security
Why prompt injection can't be patched away like SQL injection, and the layered, assume-breach approach that actually reduces risk in AI agents and Copilot deployments.